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Abstract 

We analyze various eavesdropping strategies on a quantum cryptographic channel. We present 
the optimal strategy for an eavesdropper restricted to a two-dimensional probe, interacting on-line 
with each transmitted signal. The link between safety of the transmission and the violation of 
Bell's inequality is discussed. We also use a quantum copying machine for eavesdropping and for 
broadcasting quantum information. 
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How good can a quantum "photocopy machine" be? How many pairs of people can use such a machine 
on a given 2-particle source and still violate Bell's inequality? How much information can an eavedroper 
read out of a quantum cryptography channel for a given BER (bit error rate)? Is quantum privacy 
amplification intrinsically more powerful than its classical analog, or is it only provably secure? How 
' much are the above questions related to each other? 

This letter plays with the above questions and provides several answers that in turn raise more ques- 
tions. The general motivation stems from quantum cryptography, but the problematic is more general: 
what can one do with quantum information that can not be done with classical information? Indeed, 
quantum information processing calls for original applications, not just mimicking classical applications 
in a more efficient way. Shor's factorization algorithm for example, is certainly not the end of the 
adventure, but a brilliant step that calls for more (realistic) imagination. 

The paradigm of this letter is a source of entangled EPR particles, assumed to be spin half particles, 
now known as qubits, which are shared between two users, known as Alice and Bob. One particle goes 
directly to Alice, while the other one may be modified on its way to Bob by a malevolent eavesdropper, 
known as Eve. Alice and Bob may now use various setups, either to distribute a secret key, or to test "the 
inequality" [] H . The choice of setups on both sides is summarized in Fig. [|. In the so-called BB84 or 4- 
states protocol for quantum cryptography Alice measures her particles, either in the vertical basis: J , 
or in the horizontal one: «-> . She chooses her basis at her free will (or using a "true" random generator), 
independently of all other players in the protocol. Equivalently, we could assume that Alice prepares 
particles in either basis and send them to Bob. This would be entirely equivalent for our purposes. Bob 
does precisely the same as Alice (but making independent choices) , thus measuring the particles in cither 
| or <-> bases. Alternatively, Alice and Bob may choose to use their particles to test the inequality. In this 
case, Bob simply rotates his reference frame by 45 degrees. Finally, they may use the Ekert protocol for 
quantum cryptography 0, and choose a combination of both setups, each of them now choosing between 
three possible bases. In this case, when they both use the same basis, as in the BB84 protocol, they shall 
use the data to obtain a key, while when they use different bases, they use the data to test the inequality. 

1 When John Bell was talking of his inequality, he would just say "the inequality". We shall adopt the same prescription 
in this work 
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To these ideal protocols, we shall add Eve, the malevolent eavesdropper who would like to hear what 
Alice has to say to Bob. Her aim is to obtain as much information as possible on the key exchanged 
between Alice and Bob, while creating as little disturbance as possible. Actually Eve has the most 
interesting position in this game, as, in principle, she is allowed to do everything, being only limited by 
the laws of physics (and the size of the Universe JBj). However, in order to keep the problem manageable, 
we shall impose two conditions: 

1. She interacts with only one qubit at a time. 

2. Her probe can be described by a two-dimensional Hilbert space (i.e. it is also a qubit). 

These two restrictions do limit the validity of our approach, but they are also the only realistic ones 
experimentally. Indeed, it is becoming possible to make two qubits interact with one another Ifjj, but 
more complicated systems are still quite a way off. A more general case, with an auxiliary system 
described by a four-dimensional Hilbert space, was recently described by Buzek and Hillery @, who 
devised a universal quantum-copying machine (UQCM). We shall compare this machine with a simpler 
two-dimensional one, and show that the UQCM is only marginally better. Moreover, Fuchs and Peres || 
have recently shown that, as long as the initial state of Eve's probe is a pure state, there is no need to 
go beyond a four-dimensional space. They have also shown, although only numerically, that the optimal 
detection method for a two-states system is obtained with a two-dimensional probe only. 

In Section || we find the optimal strategy for Eve using a two-dimensional probe. This strategy is better 
than the standard "intercept-resend" strategy. It is also better than a strategy that has recently been 
published 0], and was refered to as "optimal" . The reason is that || is restricted to on-line measurements: 
Eve has to perform her measurement immediately. Here, as we introduce an explicit probe, we also allow 
Eve to delay her measurement on her probe till Alice and Bob announce publicly the bases they used. 
We find also that, using this strategy, Eve can get reliable enough data to violate the inequality while 
Bob's data are still good enough to also violate the inequality! Finally, the result of this Section prove 
that quantum privacy amplification is fundamentally more efficient than classical error correction 
and privacy amplification in the sense that for high enough BER, the latter is no longer possible, whereas 
the former is still efficient. In Section || a pretty good quantum-copying machine (PGQCM) machine 
is presented. The machine itself is classical: only the original qubit and the clone are quantum, each 
represented by a 2-D Hilbert space. This pretty good machine is then compared to Buzek and Hillery R] 
UQCM. The latter requires a quantum machine, albeit the machine can also be described by a 2-D 
Hilbert space. We lend these two machines to Eve and see that using either one provides her with more 
information than the standard intercept-resend strategy, but less than the strategy studied in Section |^. 
Amusingly, we note that using such copy machine Eve can send the (perturbed) original qubit to Bobi 
and the (poor) copy to some Bob2, both Bobs violating Bell's inequalities (with respect to Alice data) 
or both Bobs establishing secret crypto keys with Alice. This provides a new way to broadcast quantum 
information, as depicted in Fig. ^[ 



2 Eavedropping with a 2-D probe 

In this Section we analyze and optimize the following eavedroping strategy for Eve. The general setting is 
depicted in Fig. [|. When Alice sends a qubit to Bob, Eve lets a second qubit (often called the probe or 
the ancilla) interact with Initially Eve's probe is in a know state |0) and the joint state of the unknown 
qubit and the probe is a product state £g> |0). This product state undergoes some unitary evolution 
after which the unknown qubit is forwarded to Bob who does his standard measurement, irrespective 
of Eve's strategy. Eve may either measure her probe immediately, as in the following measurement of 
intensity 7, or keep her probe until Alice and Bob reveal the bases used to encode this bit, and then 
measure the probe and gains information about the corresponding bit of the cryptographic key. Of course 
Eve does not need to use always the same unitary evolution. In this way she can for instance restore the 
symmetry that some evolution may break. She can also decide to reduce the perturbation, at the cost of 
reducing in the same ratio her information gain, by probing only a fraction of the unknown qubits (this 
amounts to choosing the identity as unitary evolution). We shall only consider input states of the form 
\tp(0)) — cos(#/2)| |) + sin(0/2)\ J.). On the Poincare (or Bloch) sphere these states are represented by 
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the points of a large circle that passes through the antipodic points representing | j) and | J.), and 9 is 
the angle between the directions defined by the points representing | f ) and \ip) (Fig. ||). In this way only 
real numbers need to be used. The unitary evolution is thus defined by the following real parameters dj 
and bj\ 

|T>®|0) -»oi|TT) + aa|U) + osUT) + a4|U) (1) 
1 l>®|0) -*h\ TT> + &al n) + b 3 \ 4T)+M 44) 

where unitarity implies J^j \ a j\ 2 — J2j \bj\ 2 = 1 an d J2j a jbj = 0. 

Assuming an |4 symmetry, one has bj — a^^j. Accordingly the general unitary transformation is 
determined by only 2 parameters that can be chosen as follows: 

<zi = cos a cos j3 a-i = cos a sin (3 (2) 

a 3 = sin a cos (3 <Z4 = — sin a sin (3 

For example the standard Von Neumann measurements correspond to a = /3 = 0. This example can be 
generalized to another interesting case: a — and cos(/3) 2 = 1+s 9 ln 7 ; 7 ranges between and n/2. We 
call this measurements of intensity 7, as 7 parametrizes the amount of information that Eve may obtain 
from her probe. We shall see below that, if we restrict Eve to a 2-D probe, this kind of measurement 
optimizes Eve's information gain at low BERs, and is practically indistinguishable from the optimum up 
to a BER of about 15%. First, let us rewrite the measurement of intensity 7 as follows, see Fig. [|: 

|T>®|0) -|T>®M|-7)} ( 3 ) 
|4)®|o) -u>®w| + 7)) 

When Alice sends state \tp(9)), which corresponds to the following density matrix: 

_ 1 f 1 + cos (9 sin6» \ , . 

P^-2\ sm6 1-cos^J ' (4) 

the states at the disposal of Bob and Eve, obtained by tracing out the other's qubit, read: 

1 / l + cos6> cos 7 sin d\ 
PBob = - • a 1 a ) ( 5 ) 



2 V cos 7 sin 9 1 — cos ( 



1 fl + sin 7 cos 9 cos 7 \ ,„ s 

PEvc = 7: t • I ( 6 ) 

2 V cos 7 1 — sin 7 cos ^ / 

For 7 = Eve does not introduce any errors in the transmission (the density matrix of Bob is unchanged) , 
but does not gain any information cither (her density matrix becomes independent of the initial state) . 
For positive 7 some information about 9 can be gained by measuring Eve's probe and for 7 approaching 
7r/2 this information is the optimum Von Neumann scheme (from the information point of view). Simul- 
taneously, Eve's interception introduces a perturbation on the initial state V , (^)j as shown by Eqs. (0) 
and (§). We see that when Alice and Bob use the 4 basis {9 = or 9 = n), Eve introduces no pertur- 
bation: the state received by Bob is unchanged. However, she gains information. For example, the a 
posteriori probability of having input state | |), once she has found her probe in the | f) state is: 

P(i> =T |probe =T) - 1 + & 2 ln(7) . (7) 

On the other hand, when Alice and Bob choose the <-> basis (9 = ±ir/2 ), Eve introduces errors, but 
gains no information at all (same pEvc for both inputs). Hence Eve gains nothing by waiting until she 
knows the bases: she can measure her probe immediately after it interacted with the unknown qubit. 
This is a very significant practical advantage of the measurements of intensity 7. Assuming that Alice 
and Bob chose either bases with frequency 50%, Eve's overall information gain is: 



Iae{i) = 2 



l + sin7, / l + sin7. 1 — sin7, , 1— sin 7. 
1 + s— 1 log 2 ( TT^) + 5— 1 lo g 2 ( S— 1 



(8) 
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where log 2 is the base two logarithm, to get the information in bits. 

A problem associated with these measurements however, is that the error rate depends on the basis 
used by Alice and Bob. Therefore, by checking it independently for the two bases, Alice and Bob may 
infer that the noise in their transmission is not produced by a random process. Moreover they may get 
some information about Eve's strategy. To avoid that, Eve should use a random combination of two 
measurement strategies, one along the I axis, as in Eq. (||), and one along the <-> axis. It is easy to see 
that, for this second strategy, the density matrix of the state received by Bob becomes: 

z 1 / I + COS7COS6 1 sin 9 \ , Q , 

PBob - 2 ^ sin 1 -cos 7 cos6y ' W 

so that the final density matrix, for the random combination of both strategies is: 

l/l + yycosfl 77 sin \ , . 

PBob = 77 ';„/■ 1 , (10) 



2\ r\ sin 8 1 — 77 cos ( 

where 77 = + c £ s 7 . This density matrix is now entirely symmetric with respect to the initial state. 
Indeed, if we write the initial density matrix: pAlice = 1+ "' cr , where rh = (sinfl, 0, cos 9) is the Bloch 
vector representating pAlice on the Poincare sphere, the final state is: p Bob = 1 + 7 > m, ' T _ The effect of Eve's 
eavesdropping is thus simply to "shrink" the Bloch vector by rj. 

The disturbance of the initial state increases with increasing 7, as indicated by the fidelity function: 

^( 7 ) = (m\PB 0b \m) = , (11) 



or equivalently by the BER, 5(7): 



? (7)-l-^(7) = ^W. (12) 



Eve's information gain, Eq. (^), as a function of the BER, Eq. jl^), is depicted on Fig. ||, together with 
Bob's information: Iab = 1 + <7log 2 q + (1 — q) log2(l — <?)• Fig. |5| shows that, above a BER of about 
15%, Eve may have more info than Bob, hence no classical error correction and privacy amplification 
can be applied. It is interesting to note that this simple strategy is undistinguishable from the "optimal" 
strategy of §|. 

In order to discover the quality of the simple measurements of intensity 7, we performed a computer 
optimization of Eve's information Iae for given BERs, assuming the most general eavesdropping strategy 
given by Eqs. (||) and (J3J) - In this case, the density matrix received by Bob when Alice sends state \ip{9)) 
is: 

1 / 1 + cos 9 cos 2a sin 2a cos 2(3 + sin 9 cos 2a sin 2(3 \ , . 

PBob - 2 ^ sin 2a cos 2/3 + sin 6» cos 2a sin 2/3 1- cos (9 cos 2a )' ^ } 

The density matrix received by Eve is simply obtained by interchanging a < — > (3. Similarly to the 
measurement of intensity 7, in order to avoid creating an assymmetric state for Bob, Eve has to use 
a random combination of strategies. In this case, she has to choose at random between four possible 
unitary transformations similar to Eq. (g), corresponding to four choices of symmetry breaking along 
four directions mutually orthogonal on the Poincare sphere (e.g. f, j, <— , — >). The averaged density 
matrix for Bob becomes similar to Eq. jl0|), with r\ — cos2a ( 1 + bm2 ^ m Note that, for this more general 
strategies, Eve gains information in both bases, £ and «-» . However, since this information is different 
for the two bases, it is now preferable for Eve to wait till Alice and Bob announce their bases publicly, 
before she measures her probe. The calculation of Iae as a function of a and (3 is more cumbersome 
but straightforward, and will not be presented here explicitely. The computer optimization, giving the 
best Iae at a given error rate, is represented by the upper curve of Fig. |[ The optimum strategy for 
Eve is a measurement of intensity 7 for low error rates, and remains indistinguishable from it up to a 
BER of about 15%. For example, at the crossing point between Iab and Iae, i- e - for a BER of 0.1534, 
Iae ~ 0-3816, while = 0.3820. However, above this BER value, Eve can get more information. In 
particular for large BER she can get more than 0.5 bits of information. 
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Let us now look at the case where Alice and Bob wish to test the inequality to check the integrity of 
the transmission. Following the above discussion, and since we are mainly interested in low error rates, we 
shall restrict ourselves to the measurement of intensity 7. Let us first analyze the inequality mentionned 
in the introduction (see Fig. [I]), where the reference frames of Alice and Bob are rotated by 45°. Eve's 
symmetry axis, i.e. her choice of | and J, states in Eq. 0, may be chosen along any of the axes chosen by 
Alice and Bob. We can easily calculate the value of the parameter S that appears in the CHSH version 
of Bell's inequality pl| , to get: 

Sab = V2(l + cos 7) , (14) 

(The same value is also obtained when Eve adopts the symmetrized strategy). This shows that if the 
BER is less than gecii = 1/2 — V2/4 ~ 0.1464, Alice and Bob's data violates the inequality. On the 
other hand, for the particular setup of Fig. |l|(b), for a BER above gBcii, their data does not violate the 
inequality. 

The above discussion only refers to the particular setup of Fig. 0(b), where the reference frames of 
Alice and Bob are at 45° . A more general criterion was recently given by the Horodeckis Jl2| , giving the 
necessary and sufficient condition for a density matrix to violate the CHSH inequality |ll| for at least 
one particular choice of directions. Applying first this criterion to our unsymmetrized system (i.e. Eve 
uses only one measurement of intensity 7), we found that Alice and Bob's joint density matrix fulfills this 
criterion for 7 < tt/2. Therefore, there exists one set of directions following which Alice and Bob would 
still violate some CHSH inequality till an error rate of 25%. However, if we now consider symmetrized 
strategies, which are more likely to be used by Eve in order to avoid detection, we find that the limit 
is precisely <7bc11- In other words, above this limit, the joint density matrix does not violate any CHSH 
inequality, and the above choice at 45° is optimal for testing for eavesdropping with CHSH inequalities. 

The value of gedi ~ 0.1464 is suspiciously close to the intersection of the two curves Iab and Iae, 
at a BER of 0.1534. Therefore, we make the conjecture that the real optimal strategy, which should 
be obtained with a 4-D probe, would give this very pointf]. The violation of the inequality would then 
become a interesting measure of the eavesdropping^: if the inequality is violated, Alice and Bob know 
that Eve has less mutual information than themselves, and that they can in principle perform classical 
information processing to obtain a secret key. If the inequality is not violated, then Eve may have more 
information, and so a secret key cannot be distilled by classical means. Note that the conjecture is 
restricted to symmetrized strategies, so that Alice and Bob still need to check that the error rate is the 
same for all four possible states. This conjecture is not proven yet, but at least there is no known strategy 
which contradicts it. 

However, even though above an error rate of 0.1464 Alice and Bob cannot extract a secret key by 
classical information processing, there is still something quantum hidden there. Indeed, using the so- 
called purification of entanglement jl4| , Alice and Bob may still take advantage of their system to extract 
a secret key. This procedure, known as quantum privacy amplification or QPA [jlo| , performs operations 
on two pairs of particles at a time, and can extract from the corrupted set pairs of entangled states with 
an arbitrarily high degree of entanglement, on which Eve is automatically excluded. In our case, the 
condition for this algorithm to be effective reads: 

> \ , (15) 

where = -^(| T-l) — I IT)) is the singlet state, and p the joint density matrix of Alice and Bob. This 
limit is attained for 7 = tt/2, corresponding to an error rate of 25%. This proves that QPA is not only 
"provably secure" , but is trully more powerful than any classical privacy amplification algorithm. 

Note that if Eve and Bob both do measurements in the diagonal bases, then both Eve and Bob can 
violate Bell inequality for some values of 7. Indeed when Alice and Bob use the setup of Fig. |](b), and 
Eve uses measurements of intensity 7, we find Sae — 2^2 sin 7. Both Sab and Sae are therefore larger 
than 2 for 7 around 7r/3. 

2 This conjecture seems to be validated by very recent results by Fuchs and Peres [EJ, who analyzed the optimal strategy 
(obtained with a 4-D probe). Their results show that Iab = I AE f° r a BER of 0.1464. 
3 This idea was first expressed by A. Ekert 
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3 Quantum cloning and broadcasting of quantum information 



In this Section we consider the question of (imperfect) quantum cloning and its possible application for 
eavedropping and quantum information broadcasting. First, we consider "classical" quantum cloning 
machines in which the only relevant quantum degrees of freedom are two qubits, one to be copied and 
one to receive the copy. Hence, we can use the same general frame as in the previous Section |2|, that is 
the unitary transformation defined by Eq. (Q) with the parameters a and /3 as defined by Eq. (g). In this 
case, what we want is the two density matrices peob and pEve to be equal, and as close as possible to the 
original pAiico- For the moment, the distinction between Bob and Eve is not relevant, as both now have 
the same kind of copy of the original state. However, since we later want to use this copying machine 
for eavesdropping, we keep the terminology. From Eq. (|l3|) , the two matrices are equal when a = (3. In 
order to give a quantitative measure of the quality of our cloning machine, we use the mean fidelity with 
respect to the perturbed original qubit^j: 

r (m\PB 0h \m)do . (i6) 



2tt „,. 

It is now straightforward to find the maximum value: 

;F opt = £±^« 0.825, (17) 

which is reached for a = (3 = n/12. Interestingly, it is also possible to relax the equality condition, and 
simply optimize the sum of the fidelities of the two copies. The result is the same as Eq. (p7|). We like 
to call this cloning machine a Pretty Good Quantum Copying Machine (PGQCM), for reasons described 
below. 

Fig. |^ displays the Bloch vector corresponding to the copied states for original states corresponding 
to a large circle on the Poincare sphere. Note that these are highly non symmetric. However, the 
symmetry can be restored if the cloning machine uses at random four similar unitary transformation, 
corresponding to four choices of symmetry breaking along four directions mutually orthogonal (on the 
Poincare sphere) , similarly to the previous eavesdropping strategy. This amounts to add an additional 
degree of freedom, but this one can be classical, hence easy to produce in the lab. The Bloch vector with 
such a copy machine is the same as given in Eq. ([l7|), and is also shown in Fig. [| In this case the Bloch 
vectors of the copies are the same, m cop y, and are simply related to the Bloch vector of the original qubit 
mini by TO copy = rirhinu where rj = 2T opt - 1. 

Recently Buzek and Hillery j?J have introduced another cloning machine, the UQCM (Universal 
Quantum Cloning Machine). This is a truly quantum mechanical machine in the sense that in addition 
to the minimum two qubits, the machine itself has quantum degrees of freedom, although these can be 
described by a 2-D Hilbert space with basis vectors Mj and M±. Their machine is described by the 
following unitary transformation: 

I T> ® |o> ® |M) - y|| Tt) ® |M T ) + u) + UT» ® Wi) (18) 
I T) ® |0) ® \M) - y|| U) ® \Mi) + U) + I IT)) ® |M T ) 

As for the PGQCM, the density matrices of both copies are equal. Moreover, this machine is already 
symmetric, with fidelity Funi independent of the initial state: 

^u„i = | w 0.833 . (19) 



The corresponding Bloch vector is also plotted in Fig. || Note that the UQCM has a slightly higher 
mean fidelity than the PGQCM (about 1% larger) at the cost of the complication due to the additional 
quantum degree of freedom, hence our vocabulary of "pretty good" for our PGQCM. 

4 This criterion is certainly not the only one that can be adopted, but it gives simple and reasonable results 
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Eve may use either of these copying machines to tape into Alice and Bob quantum communication 
channel. Here, contrary to the case of measurement of intensity 7 studied in Section [^, Eve gains to wait 
until Alice and Bob reveal their bases, before measuring her copy. Moreover, for the case of the UQCM, 
since the state of the machine itself after the interaction depends on the initial state, Eve may use this 
extra information contained in the machine. Her information gain for given BERs is added on Fig. |^, 
both for the PGQCM and the UQCM. We see that even the UQCM provide less information than the 
optimal strategy using only a 2-D probe. 

Finally, one may also use either cloning machines to send copies to two different Bobs, let say Bobi 
and Bob 2 . Each Bob can then independently measure his qubits. We find out that, when we use the 
assymetric PGQCM, both Bobs violate the inequality with respect to the same Alice data. It is clear 
from Fig. ||that this is dependent on the choice of directions a, a' , b and b' . For the symmetrized version, 
SaBi = Sab 2 = 2 V / 2(2JF — 1) < 2, so that there is no violation. It should also be noted that the results 
of Bobi and Bob2 are not independent, because the cloning entangles the original and the clone qubits. 

4 Conclusion 

The best possible eavesdropping strategy remains to be explored. However, we have seen that even using 
only one qubit as a probe, i.e. using techniques already under development in several labs, Eve can 
do better than the standard intercept /resend strategy. We have found the optimal strategy for such 
probes, and shown that for low BER, it is indistinguishable from a simple strategy termed measurement 
of intensity 7. This strategy puts a limit of about 15% on the BER above which Eve may possess more 
information than Bob, which means that classical information processing can not be used to distill a 
secret key. However, for the same eavesdropping strategy, quantum information processing, and more 
precisely the QPA may still be used, up to a BER of 25%-e, for any e > 0. Hence, quantum privacy 
amplification not only enables to distribute the key in a provably secure fashion, but is also intrinsically 
more powerful than its classical analog. Amusingly, using the strategy described in Section |[ Eve can 
extract enough information from the quantum channel to violate the inequality, while simultaneously 
perturbing the quantum channel so little that Bob could still violate the inequality (with respect to the 
same data of Alice). 

Perfect quantum cloning is impossible. However, an arbitrary qubit can be cloned in such a way that 
both the perturbed original qubit and the cloned qubit both have a fidelity above 80%, independently 
of the initial state to be copied. Such cloning machine can be used to broadcast quantum information, 
for quantum cryptography purposes or for the fun of multi- violation of Bell's inequalities. The Pretty 
Good Quantum Cloning machine presented in Section ||, while about 1% less efficient than the Universal 
Quantum Copy Machine, is close to feasible with todays technology. Both this PGQCM and the mea- 
surement of intensity 7 are interesting examples of potential uses for the simplest quantum gates, with 
only two interacting qubits, which are now under development in various laboratories. 
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Figures 




(a) (b) (c) 

BB84 Test of the Ekert 

cryptosystem inequality cryptosystem 

Figure 1: The various setups 
To implement the BB84 quantum cryptographic protocol, Alice and Bob use the same bases to prepare 
and measure their particles. A representation of their states on the Poincare sphere is shown in (a). A 
similar setup, but with Bob's bases rotated by 45°, can be used to test the violation of Bell inequality, 
as shown in (b) . Finally, in the Ekert protocol, Alice and Bob may use the violation of Bell inequality to 
test for eavesdropping, as shown in (c). 
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Figure 2: Broadcasting quantum information 
Quantum cloning machines (QCM) allow to broadcast quantum information, i.e. share it between various 
users, at the cost of reducing the fidelity of the channels. 




Alice Eve Bob 



Figure 3: Eavesdropping on a quantum channel 
Eve extracts information out of the quantum channel between Alice and Bob at the cost of introducing 
noise into that channel. 
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V(7t/2+y) 



Figure 4: 

State of the ancilla after the interaction corresponding to measurements of intensity 7 of an | state 
(dashed line,'i/>(7r/2 — 7)) and of a J, state (dotted line,-0(7r/2 + 7)). a corresponds to the symmetry 
breaking direction of the measurement. 



11 




Q Vi , i , i , i , i , I 

0.05 0.10 0.15 0.20 0.25 

BER 

Figure 5: 

Information gain versus Bite Error Rate (BER) for various eavesdroping strategies. The full curve 
represents the mutual information between Alice and Bob. The dotted curve is the information available 
to Eve for the intercept /resend strategy. The dashed curve is for the measurement of intensity 7. The 
dashed-dotted curve is the optimal eavesdropping strategy with a 2D probe. The circle is the information 
gained by Eve if she uses a UQCM (which requires interaction between three qubits), while the square is 
obtained by the PGQCM (which only requires interaction between two qubits). 
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Figure 6: 

Bloch vector representation of the states produced by the UQCM (full line), the PGQCM (dashes) and the 
symmetrized PGQCM (dots) corresponding to input state represented by a large circle on the Poincarc 
sphere. The directions a, a', b and b' are used for testing the inequality. We see that the choice of the 
symmetry breaking axis for the PGQCM influences the possible violation of the inequality. 
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